XylotrechusZ

XylotrechusZ Shell

: /home/matican/mail/cur/ [ drwxr-x--x ]
Uname: Linux premium72.web-hosting.com 4.18.0-553.44.1.lve.el8.x86_64 #1 SMP Thu Mar 13 14:29:12 UTC 2025 x86_64
Software: LiteSpeed
PHP version: 8.2.29 [ PHP INFO ] PHP os: Linux
Server Ip: 198.54.125.95
Your Ip: 216.73.216.35
User: matican (532) | Group: matican (531)
Safe Mode: OFF
Disable Function:
NONE

name : 1591552684.M49048P545630.premium72.web-hosting.com,S=4575,W=4662:2,
Return-Path: <>
Delivered-To: matihkpu@premium72.web-hosting.com
Received: from premium72.web-hosting.com
	by premium72.web-hosting.com with LMTP
	id 2EQ2Aqwq3V5eUwgA65zWNw
	(envelope-from <>)
	for <matihkpu@premium72.web-hosting.com>; Sun, 07 Jun 2020 13:58:04 -0400
Return-path: <>
Envelope-to: matihkpu@premium72.web-hosting.com
Delivery-date: Sun, 07 Jun 2020 13:58:04 -0400
Received: from mailnull by premium72.web-hosting.com with local (Exim 4.93)
	id 1jhzYa-002gS1-0Y
	for matihkpu@premium72.web-hosting.com; Sun, 07 Jun 2020 13:58:04 -0400
Auto-Submitted: auto-replied
From: Mail Delivery System <Mailer-Daemon@premium72.web-hosting.com>
To: matihkpu@premium72.web-hosting.com
References: <c2472e1f5a07f996d59ba572c2ecb576@www.beksolar.com>
Subject: Mail failure - rejected by local scanning code
Message-Id: <E1jhzYa-002gS1-0Y@premium72.web-hosting.com>
Date: Sun, 07 Jun 2020 13:58:04 -0400

A message that you sent was rejected by the local scanning code that
checks incoming messages on this system. The following error was given:

  "Relaying not permitted"

------ This is a copy of your message, including all the headers. ------

Received: from matihkpu by premium72.web-hosting.com with local (Exim 4.93)
	(envelope-from <matihkpu@premium72.web-hosting.com>)
	id 1jhzYZ-002gRh-W7
	for contact@wpsdfsdcharming.com; Sun, 07 Jun 2020 13:58:04 -0400
To: contact@wpsdfsdcharming.com
Subject: Your Site Has Been Hacked
X-PHP-Script: www.beksolar.com/index.php for 194.99.106.149, 194.99.106.149
X-PHP-Filename: /home/matihkpu/beksolar.com/index.php REMOTE_ADDR: 194.99.106.149
Date: Sun, 7 Jun 2020 17:58:03 +0000
From: Beksolar <contact@wpsdfsdcharming.com>
Reply-To: hacker@qtdh.com
Message-ID: <c2472e1f5a07f996d59ba572c2ecb576@www.beksolar.com>
X-Mailer: PHPMailer 5.2.27 (https://github.com/PHPMailer/PHPMailer)
MIME-Version: 1.0
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit
Sender:  <matihkpu@premium72.web-hosting.com>

From: Evangeline <hacker@qtdh.com>
Subject: Your Site Has Been Hacked

Message Body:
Phone: 02638 80 05 68
PLEASE FORWARD THIS EMAIL TO SOMEONE IN YOUR COMPANY WHO IS ALLOWED TO MAKE IMPORTANT DECISIONS!

We have hacked your website http://www.beksolar.com and extracted your databases.

How did this happen?
Our team has found a vulnerability within your site that we were able to exploit. After finding the vulnerability we were able to get your database credentials and extract your entire database and move the information to an offshore server.

What does this mean?

We will systematically go through a series of steps of totally damaging your reputation. First your database will be leaked or sold to the highest bidder which they will use with whatever their intentions are. Next if there are e-mails found they will be e-mailed that their information has been sold or leaked and your site http://www.beksolar.com was at fault thusly damaging your reputation and having angry customers/associates with whatever angry customers/associates do. Lastly any links that you have indexed in the search engines will be de-indexed based off of blackhat techniques that we used in the past to de-index our targets.

How do I stop this?

We are willing to refrain from destroying your site's reputation for a small fee. The current fee is $2000 USD in bitcoins (BTC). 

Send the bitcoin to the following Bitcoin address (Copy and paste as it is case sensitive):

12KLZzgrNX2DvbWQM7yQ1V9vPwy9JPvUKM

Once you have paid we will automatically get informed that it was your payment. Please note that you have to make payment within 5 days after receiving this notice or the database leak, e-mails dispatched, and de-index of your site WILL start!

How do I get Bitcoins?

You can easily buy bitcoins via several websites or even offline from a Bitcoin-ATM. We suggest you https://cex.io/ for buying bitcoins.

What if I don’t pay?

If you decide not to pay, we will start the attack at the indicated date and uphold it until you do, there’s no counter measure to this, you will only end up wasting more money trying to find a solution. We will completely destroy your reputation amongst google and your customers.

This is not a hoax, do not reply to this email, don’t try to reason or negotiate, we will not read any replies. Once you have paid we will stop what we were doing and you will never hear from us again!

Please note that Bitcoin is anonymous and no one will find out that you have complied.

--
This e-mail was sent from a contact form on Business Theme Demo (http://wpcharming.com/construction)

© 2025 XylotrechusZ